Question library
Incident response and claims history: what cyber insurance applications ask
Written plans, testing cadence, prior incidents, and knowledge of circumstances. The claims-history questions here carry the harshest consequence for an inaccurate answer.
7 questions in this section
attestedDoes the Applicant have a written Incident Response plan?
attestedHow frequently is the IR plan tested (quarterly/semi-annually/annually)?
attestedDoes the Applicant have a written Business Continuity Plan / Disaster Recovery Plan, tested annually?
attestedIn last 3 years, any cyber event, claim, loss, security breach, or extortion demand?
attestedAwareness of any fact / circumstance reasonably giving rise to a future claim?
attestedHas the Applicant experienced any partial or total network interruption lasting more than 8 hours?
partialAre copies of BCP/DR/IR plans stored so accessible if the Applicant's network is unavailable?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture